System and method for eliminating potential security breach when transitioning to quantum-secure environment
Abstract
A physical link is split between network devices into a first logical link and a second logical link. The first logical link is designated for communicating user data. The second logical link is designated for exchanging key identifiers (key IDs) only. The second logical link is left open and unencrypted and the key IDs are exchanged over the second logical link. Using the key IDs, quantum keys are acquired, by an agent on each respective network device, from a quantum key distribution network or subsystem. The quantum keys thus acquired are then applied to the physical link between the network devices to thereby transition the physical link between the network devices to a quantum-secure environment and open the first logical link for communicating the user data in the quantum-secure environment.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1. A method, comprising:
configuring a link for communicating user data between network devices with static keys that do not match, wherein any transmission of the user data over the link is initially blocked because the static keys do not match and continues to be blocked until quantum keys can be applied to encrypt network traffic communicated over the link;
exchanging key identifiers of the quantum keys over the link;
acquiring the quantum keys from a quantum key distribution subsystem using the key identifiers; and
applying the quantum keys to encrypt the network traffic communicated over the link between the network devices to thereby unblock the transmission of the user data and transition the link between the network devices to a quantum-secure link.
2. The method according to claim 1 , further comprising:
splitting the link between the network devices into a first logical link and a second logical link;
designating the first logical link for communicating the user data between the network devices; and
designating the second logical link for exchanging the key identifiers of the quantum keys, wherein the second logical link is left open and unencrypted.
3. The method according to claim 2 , wherein the first logical link comprises a data link and wherein the second logical link comprises a control link.
4. The method according to claim 2 , wherein the first logical link comprises a first virtualized connection and wherein the second logical link comprises a second virtualized connection.
5. The method according to claim 1 , wherein each of the network devices comprises a secure application entity (SAE), wherein the SAE runs a MACSec/QKD configuration software application that allows deployment of MACSec links with the quantum key distribution subsystem, and wherein the SAE comprises an application configured for exchanging the key identifiers, acquiring the quantum keys from the quantum key distribution subsystem using the key identifiers, and applying the quantum keys to the link between the SAEs.
6. The method according to claim 1 , wherein the quantum key distribution subsystem comprises a key management entity (KME) configured for quantum key generation and distribution.
7. The method according to claim 1 , wherein the link comprises a Media Access Control security (MACSec) link.
8. A system, comprising:
a processor;
a non-transitory computer-readable medium; and
instructions stored on the non-transitory computer-readable medium and translatable by the processor for:
configuring a link for communicating user data between network devices with static keys that do not match, wherein any transmission of the user data over the link is initially blocked because the static keys do not match and continues to be blocked until quantum keys can be applied to encrypt network traffic communicated over the link;
exchanging key identifiers of the quantum keys over the link;
acquiring the quantum keys from a quantum key distribution subsystem using the key identifiers; and
applying the quantum keys to encrypt the network traffic communicated over the link between the network devices to thereby unblock the transmission of the user data and transition the link between the network devices to a quantum-secure link.
9. The system of claim 8 , wherein the instructions are further translatable by the processor for:
splitting the link between the network devices into a first logical link and a second logical link;
designating the first logical link for communicating the user data between the network devices; and
designating the second logical link for exchanging the key identifiers of the quantum keys, wherein the second logical link is left open and unencrypted.
10. The system of claim 9 , wherein the first logical link comprises a data link and wherein the second logical link comprises a control link.
11. The system of claim 9 , wherein the first logical link comprises a first virtualized connection and wherein the second logical link comprises a second virtualized connection.
12. The system of claim 8 , wherein each of the network devices comprises a secure application entity (SAE), wherein the SAE runs a MACSec/QKD configuration software application that allows deployment of MACSec links with the quantum key distribution subsystem, and wherein the SAE comprises an application configured for exchanging the key identifiers, acquiring the quantum keys from the quantum key distribution subsystem using the key identifiers, and applying the quantum keys to the link between the SAEs.
13. The system of claim 8 , wherein the quantum key distribution subsystem comprises a key management entity (KME) configured for quantum key generation and distribution.
14. The system of claim 8 , wherein the link comprises a Media Access Control security (MACSec) link.
15. A computer program product comprising a non-transitory computer-readable medium storing instructions translatable by a processor for:
configuring a link for communicating user data between network devices with static keys that do not match, wherein any transmission of the user data over the link is initially blocked because the static keys do not match and continues to be blocked until quantum keys can be applied to encrypt network traffic communicated over the link;
exchanging key identifiers of the quantum keys over the link;
acquiring the quantum keys from a quantum key distribution subsystem using the key identifiers; and
applying the quantum keys to encrypt the network traffic communicated over the link between the network devices to thereby unblock the transmission of the user data and transition the link between the network devices to a quantum-secure link.
16. The computer program product of claim 15 , wherein the instructions are further translatable by the processor for:
splitting the link between the network devices into a first logical link and a second logical link;
designating the first logical link for communicating the user data between the network devices; and
designating the second logical link for exchanging the key identifiers of the quantum keys, wherein the second logical link is left open and unencrypted.
17. The computer program product of claim 16 , wherein the first logical link comprises a data link and wherein the second logical link comprises a control link.
18. The computer program product of claim 15 , wherein the link comprises a Media Access Control security (MACSec) link.
19. The computer program product of claim 15 , wherein each of the network devices comprises a secure application entity (SAE), wherein the SAE runs a MACSec/QKD configuration software application that allows deployment of MACSec links with the quantum key distribution subsystem, and wherein the SAE comprises an application configured for exchanging the key identifiers, acquiring the quantum keys from the quantum key distribution subsystem using the key identifiers, and applying the quantum keys to the link between the SAEs.
20. The computer program product of claim 15 , wherein the quantum key distribution subsystem comprises a key management entity (KME) configured for quantum key generation and distribution.Join the waitlist — get patent alerts
Track US12438708B2 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.